Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
78,258 exploits
GitHub PoC19
Exploit code for CVE-2019-17662
CVE-2019-1766231 Aug 2021
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RISK
open
VulnCheck XDB
initial-access
CVE-2016-10033CRITICALunder attack31 Aug 2021
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
GitHub PoC53
alt3kx/CVE-2021-26084_PoC
CVE-2021-26084CRITICALunder attackransomware31 Aug 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC4
Remote code execution vulnerability in Ruby-on-Rails when using render on user-supplied data.
CVE-2016-209831 Aug 2021
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISK
open
GitHub PoC21
CVE-2021-26084 - Confluence Pre-Auth RCE | OGNL injection
CVE-2021-26084CRITICALunder attackransomware31 Aug 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
Exploit-DB
Umbraco CMS 8.9.1 - Directory Traversal
CVE-2020-5811webappsaspx31 Aug 2021
An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, whi
23RISK
open
VulnCheck XDB
initial-access
CVE-2021-33766HIGHunder attack31 Aug 2021
Microsoft Exchange Server Information Disclosure Vulnerability
100RISK
open
GitHub PoC1
Remote Code Execution vulnerability in PHPMailer.
CVE-2016-10033CRITICALunder attack31 Aug 2021
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALunder attackransomware31 Aug 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
Exploit-DB
WordPress Plugin ProfilePress 3.1.3 - Privilege Escalation (Unauthenticated)
CVE-2021-34621CRITICALwebappsphp31 Aug 2021
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
75RISK
open
GitHub PoC48
ProxyToken (CVE-2021-33766) : An Authentication Bypass in Microsoft Exchange Server POC exploit
CVE-2021-33766HIGHunder attack31 Aug 2021
Microsoft Exchange Server Information Disclosure Vulnerability
100RISK
open
GitHub PoC
https://www.exploit-db.com/exploits/49757
CVE-2011-252331 Aug 2021
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
Exploit-DB
Strapi 3.0.0-beta.17.7 - Remote Code Execution (RCE) (Authenticated)
CVE-2019-19609webappsmultiple30 Aug 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISK
open
GitHub PoC
Strapi <= 3.0.0-beta.17.8 authenticated remote code execution
CVE-2019-1960930 Aug 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISK
open
Exploit-DB
Strapi 3.0.0-beta - Set Password (Unauthenticated)
CVE-2019-18818webappsmultiple30 Aug 2021
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-1960930 Aug 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISK
open
VulnCheck XDB
initial-access
CVE-2020-25223CRITICALunder attack29 Aug 2021
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-19781CRITICALunder attackransomware29 Aug 2021
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-1881829 Aug 2021
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-1960929 Aug 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-1960929 Aug 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISK
open
GitHub PoC11
CVE-2020-25223
CVE-2020-25223CRITICALunder attack29 Aug 2021
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511
100RISK
open
GitHub PoC1
Citrix ADC RCE cve-2019-19781
CVE-2019-19781CRITICALunder attackransomware29 Aug 2021
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
GitHub PoC
BabyTeam1024/CVE-2017-3248
CVE-2017-324829 Aug 2021
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Suppo
60RISK
open
GitHub PoC7
Strapi Framework Vulnerable to Remote Code Execution
CVE-2019-1960929 Aug 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISK
open
GitHub PoC3
guglia001/CVE-2019-18818
CVE-2019-1881829 Aug 2021
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISK
open
GitHub PoC9
Exploit for CVE-2019-19609 in Strapi (Remote Code Execution)
CVE-2019-1960929 Aug 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISK
open
GitHub PoC1
CVE-2004-2687 DistCC Daemon Command Execution
CVE-2004-268728 Aug 2021
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote at
60RISK
open
GitHub PoC
AssassinUKG/CVE-2021-29447
CVE-2021-29447HIGH27 Aug 2021
WordPress Authenticated XXE attack when installation is running PHP 8
63RISK
open
GitHub PoC1
A proof of concept for CVE-2016-6515
CVE-2016-651526 Aug 2021
The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password a
35RISK
open
previouspage 667 / 2,609next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.